FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
TT
20

FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, the FBI said in an advisory sent to US companies obtained by CNN.

The Iranian hackers have taken an interest in dark-web forums, where scammers leak information on their victims such as stolen emails and network configurations, according to the November 8 advisory. The FBI is concerned that the Iranian hacking group could use that information to plot ways into US corporate networks in the future.

Organizations at risk are advised to take mitigation measures to block hacking attempts by securing Remote Desktop Protocol (RDP) servers, Web Application Firewalls, and Kentico CMS installations targeted by this adversary, said Bleeping Computer, a cybersecurity news outlet, which was the first to report on the FBI analysis.

"Among the Tactics, Techniques, and Procedures (TTPs) used in attacks by this threat actor since May 2021, the FBI mentions the use of auto-exploiter tools used to compromise WordPress sites to deploy web shells, breaching RDP servers and using them to maintain access to victims' networks."

It is unclear which Iranian hacking group is behind the activity. The FBI did not identify the hackers by name or say if they are linked to the Iranian government.

Adam Meyers, senior vice president of intelligence at security firm CrowdStrike, told CNN that Iranian government-linked hackers have increasingly dabbled in cybercriminal activity, such as ransomware, as a means of blurring the lines between state and non-state cyber operations.

"It is well within (Iranian groups') modus operandi to purchase access to networks held by a criminal group if it serves their interests," he added.

An unnamed Iranian hacking group used similar tools to steal voter registration data from state election sites between September and October 2020, Bleeping Computer.

"That voter info was later used to impersonate the far-right Proud Boys organization and send threatening emails to Democratic voters warning that they must vote for Trump or face the consequences."

"The FBI's Cyber Division also warned in a private industry notification issued last week that ransomware gangs have compromised the networks of several tribal-owned casinos, taking down their servers and disabling connected systems."

"The same week, the federal agency also alerted the public that criminals are increasingly using cryptocurrency ATMs and QR codes for fraud, making it harder for law enforcement to recover the victims' financial losses."



Ukraine’s Zelenskiy Says There Is Now a Good Chance to End War

 Ukraine’s President Volodymyr Zelenskiy speaks to Ukrainian Muslim service members before sharing an iftar with them, a meal to break their fast at sunset, during the holy month of Ramadan, in a mosque in Kyiv, Ukraine March 13, 2025. (Reuters)
Ukraine’s President Volodymyr Zelenskiy speaks to Ukrainian Muslim service members before sharing an iftar with them, a meal to break their fast at sunset, during the holy month of Ramadan, in a mosque in Kyiv, Ukraine March 13, 2025. (Reuters)
TT
20

Ukraine’s Zelenskiy Says There Is Now a Good Chance to End War

 Ukraine’s President Volodymyr Zelenskiy speaks to Ukrainian Muslim service members before sharing an iftar with them, a meal to break their fast at sunset, during the holy month of Ramadan, in a mosque in Kyiv, Ukraine March 13, 2025. (Reuters)
Ukraine’s President Volodymyr Zelenskiy speaks to Ukrainian Muslim service members before sharing an iftar with them, a meal to break their fast at sunset, during the holy month of Ramadan, in a mosque in Kyiv, Ukraine March 13, 2025. (Reuters)

Ukrainian President Volodymyr Zelenskiy said on Friday that he saw a good chance to end the war with Russia after Ukraine accepted a US proposal for a 30-day interim ceasefire and Moscow said it would only agree if certain conditions were met.

"Right now, we have a good chance to end this war quickly and secure peace. We have solid security understandings with our European partners," Zelenskiy said on X.

"We are now close to the first step in ending any war – silence," he said, referring to a truce.

Speaking to reporters, Zelenskiy urged the US and other allies to apply pressure on Moscow, reiterating his belief that Russian President Vladimir Putin will delay reaching a ceasefire as long as possible.

"If there is a strong response from the United States, they will not let them play around. And if there are steps that Russia is not afraid of, they will delay the process," Zelenskiy told media.

He said that the ceasefire along a more than 1,000-kilometer (600-mile) frontline could be controlled with US help via satellites and intelligence. Washington resumed intelligence sharing and military aid after US and Ukrainian officials met in Saudi Arabia this week and Ukraine accepted the ceasefire.

Zelenskiy also said that officials at that meeting discussed the issue of territory, but a difficult dialog would be required to resolve it.

"The issue of territories is the most difficult after the ceasefire," Zelenskiy said at a media briefing.

With the war is in its fourth year, Russian forces control nearly a fifth of Ukrainian territory and they have steadily advanced in the eastern Donetsk region in recent months.

"The ceasefire unblocks the way for the sides to end the war. And the territories ... will be the point that makes it possible to end the war after this issue is resolved," the Ukrainian president said.

Moscow has demanded that Kyiv permanently cede territory claimed by Russia including Crimea and four other regions, a position Ukraine has rejected.

Zelenskiy said he was discussing with Kyiv's allies future security guarantees and also economic support, adding that 100% air defense cover would be required as deterrence in a peace deal.